I keep seeing the same pattern: take an LLM, give it access to kubectl or the k8s API, write something like "you can only read, don't delete or modify anything" in the system prompt or an attached skill, and consider the problem solved. I went through this myself and at some point realized that ...
Source: [Dev.to](https://dev.to/granite-so/read-only-kubernetes-access-for-ai-agents-why-please-dont-delete-anything-isnt-a-security-2cem)